Insufficient Input Validation in NetScaler ADC and Gateway by Citrix
CVE-2026-8451
Key Information:
Badges
What is CVE-2026-8451?
CVE-2026-8451 is a vulnerability found in the Citrix NetScaler ADC (Application Delivery Controller) and NetScaler Gateway. These products are designed to optimize application delivery, enhance security, and provide remote access for users. Specifically, the vulnerability arises from insufficient input validation when the NetScaler ADC or Gateway is configured as a SAML (Security Assertion Markup Language) Identity Provider (IDP). This weakness can lead to memory overread, which could allow unauthorized access to sensitive information stored in memory. Organizations that rely on these systems for secure application delivery might face significant repercussions if exploited, including unauthorized data exposure or potential system instability.
Potential impact of CVE-2026-8451
-
Data Exposure: The insufficient input validation could lead to attackers gaining access to sensitive data stored in memory, which may include user credentials, session tokens, or other confidential records.
-
System Disruption: Memory overread vulnerabilities can cause instability in affected systems, potentially leading to application crashes or degraded performance, disrupting critical business operations.
-
Increased Attack Vulnerability: This vulnerability can serve as a stepping stone for further attacks, allowing attackers to leverage the same weaknesses to escalate privileges or introduce additional exploits, thereby broadening the attack surface for organizations.
Affected Version(s)
ADC 14.1 < 72.61
ADC 13.1 < 63.18
ADC 14.1 FIPs < 72.61
News Articles
CitrixBleed-ing Again? NetScaler Vulnerability Under Attack
Attackers wasted little time targeting the latest memory disclosure bug in Citrix NetScaler, after researchers published a proof-of-concept exploit.
2 weeks ago
CitrixBleed Vulnerability Exploitation Within 24 Hours of Disclosure - IT Security News
Citrix NetScaler appliances are currently facing significant threats due to the rapid exploitation of a newly disclosed memory disclosure vulnerability, CVE-2026-8451, which is part of the evolving “CitrixBleed” class. This high-severity flaw (CVSS 8.8), disclosed on June 30, 2026, in…Read more →
3 weeks ago
CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public Disclosure
A newly disclosed CitrixBleed-class vulnerability in Citrix NetScaler appliances came under active exploitation less than a day after public disclosure.
3 weeks ago

References
CVSS V4
Timeline
- 💰
Used in Ransomware
- 🥇
Vulnerability reached the number 1 worldwide trending spot
- 📈
Vulnerability started trending
- 👾
Exploit known to exist
- 📰
First article discovered by Esecurity Planet
Vulnerability published
Vulnerability Reserved